Chapter 3 of 6 · Before you start

Microsoft Foundry platform baseline, inventory, and landing-zone guardrails

Governed foundation 5 hours in a non-production POC

Chapter 3 of 6

Confirm these requirements:

  • The approved subscription, resource group, regions, network pattern, tags, owners, and change record are recorded. The cloud platform owner confirms that they name the same approved scope.
  • The deployment operator has time-bound Contributor on the exact approved sandbox resource group and time-bound Resource Policy Contributor on the approved subscription.
  • The operator can run deployment what-if at resource-group and subscription scope.
  • The cloud platform owner has reviewed inherited policy assignments and exemptions.
  • The required Azure resource providers are registered.

Use team aliases and synthetic classifications in tags. Do not place credentials, resource IDs, endpoints, prompts, traces, responses, or customer data in parameters, tags, outputs, or source control.

Implementation files#

TypeFileConsumer
Deploymentartifacts/infra/foundry/main.bicepThe platform deployment pipeline
Deploymentartifacts/infra/network/main.bicepThe platform deployment pipeline
Deploymentartifacts/environments/sandbox.bicepparamThe platform deployment pipeline
Deploymentartifacts/environments/network-foundation.bicepparamThe platform deployment pipeline
Deploymentartifacts/policy/initiative.bicepThe subscription policy deployment pipeline
Deploymentartifacts/policy/assignment.bicepThe sandbox policy deployment pipeline
Deploymentartifacts/policy/guardrail-settings.jsonThe initiative and assignment parameter builds
Deploymentartifacts/environments/initiative.bicepparamThe subscription policy deployment pipeline
Deploymentartifacts/environments/policy-assignment.bicepparamThe sandbox policy deployment pipeline

Session 01

Microsoft Foundry platform baseline, inventory, and landing-zone guardrails slide deck